Why starting a fraud data sharing community is harder than it looks

The benefits are clear — collective defence, faster detection, regulatory goodwill. But standing one up means tackling a long list of hard problems:

You don’t have to figure all of this out yourself. That’s what we do.

What your fraud data sharing community will look like with our help

Imagine your community is up and running. Members trust each other, intelligence flows in near real-time, and every participant — from the smallest institution to the largest — is getting value. Here’s what that looks like day to day.

  • Clear focus — The community has a well-defined niche. Every member knows exactly what types of fraud data are shared, what is in scope, and what is not.
  • Trusted membership — Members are vetted and onboarded with clear expectations. Every participant has confidence in who they are sharing with.
  • Data you can act on — Shared indicators are triaged before they reach members. False positives are low, context is rich, and members act on what they receive because they trust it.
  • Governance that works — Data-handling policies, sharing agreements, and escalation procedures are documented, understood, and followed. Legal and compliance teams are on board.
  • Sustainable operations — The community has a funding model, a team keeping the platform running, and processes that don’t depend on a single champion.
  • A community that shows up — Members attend regular meetings, share back what they learn, onboard their teams, and advocate internally for continued participation.

Share with community members of different maturity levels

1
Getting started
Members at the earliest stage of maturity consume PDFs and reports over email
2
Basic automation
Members at the next level of maturity grab files from an SFTP server or download from a webpage
3
Platform integration
More mature members pull structured indicators directly from the MISP platform
4
Full participation
The highest maturity members do bidirectional sync: consuming shared data and contributing back to the community

Want to know how mature you are? We measure your maturity using the CTI-CMM Framework. Learn more here.

We tailor our guidance to the specific needs of each community.

We help launch every type of fraud data sharing community

REGULATORY
Regulator-Mandated Communities
Central banks and financial regulators requiring structured fraud data reporting from supervised institutions.
CONSORTIUM
Bank-to-Bank Peer Networks
Groups of banks sharing fraud indicators, mule account data, and emerging typologies directly with each other.
ISACISAO
Sector ISACs & ISAOs
Industry-specific Information Sharing and Analysis Centers coordinating fraud and threat intelligence across member organisations within a sector.
PAYMENTSFINTECH
Payment Ecosystem Sharing
Payment processors, card networks, and fintechs exchanging fraud signals across the transaction lifecycle.
PPPGOV
Public-Private Partnerships
Government agencies and financial institutions collaborating on national or sectoral fraud prevention programmes.
What we can help you with
Fluffy white clouds against a dark blue sky
Platform
CloudMISP as your sharing hub
A fully managed MISP instance deployed in your preferred AWS region, with enterprise-grade reliability and support.
  • Automated backups, patching, and 24/7 monitoring
  • Member isolation and sharing groups configured for your community
  • Custom taxonomies and tagging to match your fraud data model
Learn more about CloudMISP
A person using a laptop computer on a desk
Governance
Community design and member onboarding
Hands-on consulting to stand up your community and get members sharing.
  • Draft governance charters, data-handling policies, and membership agreements
  • Configure MISP instances and sharing workflows for each member
  • Run onboarding workshops so new members contribute from week one
Learn more about our Consulting
Abstract network of threads and nodes on pins
Integrations
Integrations and ongoing support
Custom connectors between member fraud systems, regulators, and the sharing platform.
  • Build and maintain STIX/TAXII, REST API, and MISP feed integrations
  • Automate ingestion, enrichment, and dissemination pipelines
  • The same platform supports cyber threat intelligence sharing alongside fraud data
Learn more about our Consulting
Why work with us

Fraud data sharing community experience you can trust

Designed and launched sharing communities for central banks and government agencies
Operated national-scale sharing platforms including Australia's national threat sharing program
Built CloudMISP as a purpose-built managed platform for multi-party fraud data sharing
Deep understanding of the governance, funding, and social dynamics that make communities succeed
Terry MacDonald presenting at NZITF
Cosive co-founder Terry MacDonald presenting at the NZITF Conference.

Common questions about starting a fraud data sharing community

Can you help me plan a new sharing community?

Yes. We help with every stage of community planning — from identifying your community niche and defining membership requirements, to designing governance frameworks, funding models, and the technical infrastructure that underpins it all.

Whether you're a central bank, government agency, or industry body, we'll work with you to design a community that fits your sector's needs and regulatory context.

What fraud data sharing platforms do you support?

We support a range of platforms and standards for community-based sharing:

CloudMISP — Our fully managed MISP platform, purpose-built for multi-party fraud data sharing with member isolation, sharing groups, and enterprise-grade operations.

We also support self-hosted MISP, STIX/TAXII-based exchanges, and custom API integrations. If your community has specific platform requirements, we can adapt to them.

My regulator's platform isn't listed. Can you support my regulator?
Yes. We've worked with regulators globally and can support any structured data exchange requirement. We'll work with you to understand your regulator's specific format, reporting cadence, and connectivity requirements, then configure the platform accordingly.
How do you help onboard new members into a sharing community?
Getting member organisations from “interested” to “actively sharing” is the hardest part of running a community. We make onboarding frictionless by handling the technical setup — provisioning accounts, configuring sharing groups and access controls, and integrating the platform with each member's existing fraud or security tools via API. We also run analyst workshops that cover what to share, how to structure indicators, and how to get value from community data. New members can start by consuming shared intelligence before they're ready to contribute, which lowers the barrier to entry. After go-live we help community operators spot inactive members and re-engage them so the community keeps growing. We've done this at national scale with Australia's threat sharing program. Talk to us about member onboarding.
Can you also help me share cyber threat intelligence?
Yes. The same platform that supports fraud data sharing can also be used for cyber threat intelligence. Many communities share both. Learn more about our cyber threat intelligence services.
Why would my bank share fraud data with competitors?

Fraud rings don't target one bank at a time — they hit multiple institutions simultaneously. No single bank sees the full picture, which is exactly what the attackers rely on. Sharing mule account indicators, fraud typologies, and emerging scheme patterns across banks means every member detects attacks faster and with more confidence.

The key concern we hear from CISOs is loss of control over sensitive data. MISP's sharing groups and granular access controls address this directly: each bank decides exactly what it shares, with whom, and under what terms. Proprietary customer data never leaves your organisation — what gets shared are anonymised indicators and tactical patterns that help the whole community defend better.

This isn't theoretical. Communities like the UK's CIFAS and Australia's AFP-led fraud intelligence program have proven the model at scale. The net effect is straightforward: your own detection rates improve as other members contribute their observations, and you gain early warning of schemes before they reach your customers.

How does a sharing community help us meet regulatory expectations?

Regulators increasingly expect financial institutions to actively participate in fraud intelligence sharing — not just file compliance reports after the fact. Running or joining a structured sharing community demonstrates proactive risk management to your supervisors and positions your institution as a responsible actor in the financial ecosystem.

Emerging regulations are making this expectation explicit. The EU's PSD3/PSR framework, the UK's APP fraud measures, and similar obligations in Australia all point toward mandatory participation in fraud data sharing. A community built on a platform like CloudMISP means you're already ahead of these requirements rather than scrambling to comply after they take effect.

From a practical standpoint, the platform's logging and reporting capabilities produce audit-ready evidence of your sharing activity. When a supervisor asks what your institution is doing to combat fraud collaboratively, you have a clear, documented answer — complete with participation metrics, sharing volumes, and contribution history.

Network globe visualization

How can we help?

Tell us about your plans for a fraud data sharing community and we'll get back to you as soon as possible.